# Virtual Networks, Subnets and NSGs — Azure

Source: https://www.skillbyai.com/en/azure/n-vnet

> Design a VNet address plan and filter traffic with network security groups.

## Your private network in Azure

A **virtual network (VNet)** is an isolated private network in one region with an address space you choose, such as `10.10.0.0/16`, divided into **subnets** (`10.10.1.0/24` for web, `10.10.2.0/24` for data). Azure reserves five addresses in every subnet. **Network security groups (NSGs)** filter traffic with ordered allow/deny rules on source, destination, port and protocol; rules with **lower priority numbers are evaluated first** (100 to 4096), and default rules allow traffic inside the VNet and block inbound from the internet. NSGs attach to subnets or network interfaces. **VNet peering** connects VNets privately over Microsoft's backbone, but it is **not transitive**: if A peers with B and B with C, A cannot reach C without its own peering or a hub with routing. Common designs use a **hub-and-spoke** layout, with shared firewalls and gateways in the hub. Prefer **Azure Bastion** over public SSH or RDP ports.

## Hub and spokes

Shared services live in a hub VNet; each workload gets a spoke peered to the hub.

![A central hub circle connected by lines to four spoke boxes, each spoke subdivided into smaller subnet strips.](assets/figures/azure/section-6-map.svg) — Figure 6.1 — A hub-and-spoke network with subnets in each spoke.

## VNet, subnets and a tight NSG rule

Allow HTTPS to the web subnet only from the application gateway subnet.

```bash
az network vnet create -g rg-shop-dev-cin -n vnet-shop --address-prefixes 10.10.0.0/16 \
  --subnet-name snet-web --subnet-prefixes 10.10.1.0/24
az network vnet subnet create -g rg-shop-dev-cin --vnet-name vnet-shop -n snet-data --address-prefixes 10.10.2.0/24

az network nsg create -g rg-shop-dev-cin -n nsg-web
az network nsg rule create -g rg-shop-dev-cin --nsg-name nsg-web -n allow-https-from-agw \
  --priority 100 --direction Inbound --access Allow --protocol Tcp \
  --source-address-prefixes 10.10.0.0/24 --destination-port-ranges 443
az network vnet subnet update -g rg-shop-dev-cin --vnet-name vnet-shop -n snet-web --network-security-group nsg-web
```

## Plan address space before you peer

Peered VNets cannot have overlapping address ranges, and neither can VNets connected to your office network. Agree on a company-wide IP plan early; re-addressing a live VNet is painful.

**Quiz:** VNet A is peered with B, and B is peered with C. Can A reach C directly?

- [ ] Yes, peering is transitive
- [ ] Only if all three are in the same subscription
- [x] No, peering is not transitive without extra routing or a direct peering
- [ ] Only over the public internet

*Answer:* No, peering is not transitive without extra routing or a direct peering. VNet peering is non-transitive; you need a direct peering or a hub with a router or firewall.
